Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and documents use of environment variables and networked services, but does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: users or platforms may believe the skill is more limited than it actually is, while it can access secrets like HF_TOKEN and send data to external endpoints.
